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New Cryptocurrency Mining Malware Has Links to North Korea 


A malware tool for stealthily installing software that mines the Monero virtual currency looks like the 

handiwork of North Korean threat actors, Alien Vault says. 


A security vendor has found another clue that North Korea may be turning to illegal cryptocurrency mining as a way 
to bring cash into the nation's economy amid tightening international sanctions. 

AlienVault on Monday said it had recently discovered malware that is designed to stealthily install a miner for 
Monero, a Bitcoin-like cryptocurrency, on end-user systems and to send any mined coins to the Kim II Sung 

University (KSU) in Pyongyang. 

The malicious installer appears to have been created just before Christmas 2017 and is designed to install xmrig, an 

open source miner for Monero. 

The link to the university itself doesn't appear to be working, however, meaning the software cannot send any mined 
coins back to its authors. The malware itself appears pretty basic, and the inclusion of the KSU server in the code 
could simply be a false flag to trick security researchers. Even so, the malware is consistent with previous similar 

campaigns tied to North Korea, AlienVault said. 

"Cryptocurrencies could provide a financial lifeline to a country hit hard by sanctions," the vendor said. "Therefore 
it's not surprising that universities in North Korea have shown a clear interest in cryptocurrencies." 

A cryptocurrency mining tool like xmrig is basically designed to harness the processing power of a computer in 
order to verify transactions in a blockchain. Users who put their computers to work mining virtual currencies such as 
Bitcoin and Monero typically receive small monetary rewards for allowing their hardware to be used for the purpose. 

Crypto mining is legitimate activity. Some, like Coinhive, even distribute miners to website operators so users can 
run it in their browsers in exchange for an ad-free experience. In recent years, though, cybercriminals have 
increasingly begun hijacking computers in order to mine cryptocurrency for illegal profit. 

In a report last September, IBM said that between January and July 2017 it had seen a six-fold increase in CPU 
mining attacks involving the use of malware for installing virtual currency mining tools against its customers. The 
tools typically were embedded in fake image fdes that were hosted on infiltrated servers running WordPress or 
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Joomla. Most of the attacks that IBM analyzed were designed to target virtual currencies such as Monero, whose 
CryptoNight algorithm can run on ordinary PCs and servers compared to the specialized hardware required for 

Bitcoin mining. 
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Last September, Kaspersky Lab re ported finding two relatively large botnets comprised of computers infected with 
malware for installing legitimate cryptocurrency miners on them. The security vendor estimated that a 4,000- 
computer botnet used for cryptocurrency mining was netting its operators up to $30,000 a month, while a bigger 
5,000-computer botnet was garnering its operators some $200,000 a month. 

"As the price of crypto-currencies increase, so do the incentives to infect people with mining malware," says Chris 
Doman, security researcher at Alien Vault. "Monero is becoming a popular choice as it is both more anonymous and 

more profitable to mine with malware." 

Security researchers have found plenty of clues in recent months to suggest that Korea-linked threat actors like the 
Lazarus Group and others are actively engaged in cryptocurrency mining. Earlier this month, Bloomber g reported an 
incident in which a North Korea threat group called Andariel hijacked a server belonging to a South Korean 

organization and used it to mine about 70 Montero coins. 

The Lazarus group has been caught doing Monero mining on compromised networks and attacking Bitcoin 
exchanges, Doman says. There have also been several public reports of North Korean universities looking into 
mining cryptocurrencies, Doman says. So while it is hard to say with complete certainty if the malware that 
Alien Vault discovered is the work of North Korean actors, chances are high it is, he notes. 

"The main takeaway for me is that this fits into the larger picture of North Korea and cryptocurrencies." 
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Enterprise Vulnerabilities 

From DHS/US-CERT's National Vulnerability Database 

CVE-2017-0290 

Published: 2017-05-09 

NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as 
used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a 
denial of service (type confusion and application crash) via crafted JavaScript code within ... 

CVE-2016-10369 

Published: 2017-05-08 

unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a 
denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access 

control). 

CVE-2016-8202 

Published: 2017-05-08 

A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS 
(FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges 
of user accounts accessing the system via command line interface. With affected version... 

CVE-2016-8209 

Published: 2017-05-08 

Improper checks for unusual or exceptional conditions in Brocade Netlron 05.8.00 and later releases up to 
and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow 
attackers to cause a denial of service (crash and reload) of the management module. 

CVE-2017-0890 

Published: 2017-05-08 

Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the 
search module. To be exploitable a user has to write or paste malicious content into the search dialogue. 
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